{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:30:39Z","timestamp":1780633839826,"version":"3.54.1"},"reference-count":48,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2019,1,20]],"date-time":"2019-01-20T00:00:00Z","timestamp":1547942400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2019,11]]},"DOI":"10.1007\/s13389-018-00200-4","type":"journal-article","created":{"date-parts":[[2019,1,20]],"date-time":"2019-01-20T07:07:11Z","timestamp":1547968031000},"page":"341-357","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["A toolbox for software optimization of QC-MDPC code-based cryptosystems"],"prefix":"10.1007","volume":"9","author":[{"given":"Nir","family":"Drucker","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shay","family":"Gueron","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,1,20]]},"reference":[{"issue":"5","key":"200_CR1","doi-asserted-by":"publisher","first-page":"3927","DOI":"10.1109\/TIT.2018.2804444","volume":"64","author":"C Aguilar","year":"2018","unstructured":"Aguilar, C., Blazy, O., Deneuville, J.C., Gaborit, P., Z\u00e9mor, G.: Efficient encryption from random quasi-cyclic codes. IEEE Trans. Inf. Theory 64(5), 3927\u20133943 (2018)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"200_CR2","unstructured":"Aragon, N., Barreto, P.S.L.M., Bettaieb, S., Bidoux, L., Blazy, O., Deneuville, J.-C., Gaborit, P., Gueron, S., Guneysu, T., Melchor, C.A., Misoczki, R., Persichetti, E., Sendrier, N., Tillich, J.P., Z\u00e9mor, G.: BIKE: Bit Flipping Key Encapsulation. https:\/\/bikesuite.org\/spec.html (2017). Retrieved 8 Jan 2019"},{"key":"200_CR3","doi-asserted-by":"crossref","unstructured":"Baldi, M., Chiaraluce, F., Garello, R.: On the usage of quasi-cyclic low-density parity-check codes in the McEliece cryptosystem. In: 2006 First International Conference on Communications and Electronics, pp. 305\u2013310 (2006). https:\/\/doi.org\/10.1109\/CCE.2006.350824","DOI":"10.1109\/CCE.2006.350824"},{"key":"200_CR4","doi-asserted-by":"crossref","unstructured":"Baldi, M., Chiaraluce, F., Garello, R., Mininni, F.: Quasi-cyclic low-density parity-check codes in the McEliece cryptosystem. In: 2007 IEEE International Conference on Communications, pp. 951\u2013956 (2007). https:\/\/doi.org\/10.1109\/ICC.2007.161","DOI":"10.1109\/ICC.2007.161"},{"key":"200_CR5","first-page":"246","volume-title":"Lecture Notes in Computer Science","author":"Marco Baldi","year":"2008","unstructured":"Baldi, M., Bodrato, M., Chiaraluce, F.: A new analysis of the McEliece cryptosystem based on QC-LDPC codes. In: Security and Cryptography for Networks, pp. 246\u2013262 (2008)"},{"key":"200_CR6","first-page":"1","volume-title":"Using LDGM Codes and Sparse Syndromes to Achieve Digital Signatures","author":"M Baldi","year":"2013","unstructured":"Baldi, M., Bianchi, M., Chiaraluce, F., Rosenthal, J., Schipani, D.: Using LDGM Codes and Sparse Syndromes to Achieve Digital Signatures, pp. 1\u201315. Springer, Berlin (2013)"},{"key":"200_CR7","doi-asserted-by":"crossref","unstructured":"Barker, E.B., Kelsey, J.M.: SP 800-90A. Recommendation for random number generation using deterministic random bit generators. Tech. rep., NIST, Gaithersburg, MD, United States (2012)","DOI":"10.6028\/NIST.SP.800-90a"},{"key":"200_CR8","doi-asserted-by":"crossref","unstructured":"Barreto, P.S., Gueron, S., Gueneysu, T., Misoczki, R., Persichetti, E., Sendrier, N., Tillich, J.P.: CAKE: Code-based Algorithm for Key Encapsulation. In: IMA International Conference on Cryptography and Coding, pp. 207\u2013226. Springer (2017)","DOI":"10.1007\/978-3-319-71045-7_11"},{"key":"200_CR9","unstructured":"Barreto, P.S.L.M.: Private communication (2017)"},{"key":"200_CR10","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1007\/978-3-540-73074-3_10","volume-title":"Arithmetic of Finite Fields","author":"M Bodrato","year":"2007","unstructured":"Bodrato, M.: Towards optimal Toom\u2013Cook multiplication for univariate and multivariate polynomials in characteristic 2 and 0. In: Carlet, C., Sunar, B. (eds.) Arithmetic of Finite Fields, pp. 116\u2013133. Springer, Berlin (2007)"},{"key":"200_CR11","doi-asserted-by":"publisher","first-page":"138","DOI":"10.1007\/978-3-642-30057-8_9","volume-title":"Efficient Implementation of a CCA2-Secure Variant of McEliece Using Generalized Srivastava Codes","author":"PL Cayrel","year":"2012","unstructured":"Cayrel, P.L., Hoffmann, G., Persichetti, E.: Efficient Implementation of a CCA2-Secure Variant of McEliece Using Generalized Srivastava Codes, pp. 138\u2013155. Springer, Berlin (2012). https:\/\/doi.org\/10.1007\/978-3-642-30057-8_9"},{"key":"200_CR12","doi-asserted-by":"crossref","unstructured":"Chaulet, J., Sendrier, N.: Worst case QC-MDPC decoder for McEliece cryptosystem. In: 2016 IEEE International Symposium on Information Theory (ISIT), pp. 1366\u20131370 (2016). https:\/\/doi.org\/10.1109\/ISIT.2016.7541522","DOI":"10.1109\/ISIT.2016.7541522"},{"key":"200_CR13","doi-asserted-by":"publisher","first-page":"291","DOI":"10.1090\/S0002-9947-1969-0249212-8","volume":"142","author":"SA Cook","year":"1969","unstructured":"Cook, S.A., Aanderaa, S.O.: On the minimum computation time of functions. Trans. Am. Math. Soc. 142, 291\u2013314 (1969)","journal-title":"Trans. Am. Math. Soc."},{"key":"200_CR14","doi-asserted-by":"crossref","unstructured":"Courtois, N.T., Finiasz, M., Sendrier, N.: How to achieve a McEliece-based digital signature scheme. In: International Conference on the Theory and Application of Cryptology and Information Security, pp. 157\u2013174. Springer (2001)","DOI":"10.1007\/3-540-45682-1_10"},{"key":"200_CR15","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1007\/978-3-319-59879-6_2","volume-title":"Ouroboros: A Simple, Secure and Efficient Key Exchange Protocol Based on Coding Theory","author":"JC Deneuville","year":"2017","unstructured":"Deneuville, J.C., Gaborit, P., Z\u00e9mor, G.: Ouroboros: A Simple, Secure and Efficient Key Exchange Protocol Based on Coding Theory, pp. 18\u201334. Springer International Publishing, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-59879-6_2"},{"key":"200_CR16","doi-asserted-by":"crossref","unstructured":"Drucker, N., Gueron, S.: A-toolbox-for-software-optimization-of-qc-mdpc-code-based-cryptosystems. https:\/\/github.com\/Shay-Gueron\/A-toolbox-for-software-optimization-of-QC-MDPC-code-based-cryptosystems (2017). Accessed 1 Jan 2019","DOI":"10.1007\/s13389-018-00200-4"},{"key":"200_CR17","unstructured":"Drucker, N., Gueron, S.: Additional implementation of BIKE. https:\/\/bikesuite.org\/additional.html (2018). Retrieved 8 Jan 2019"},{"issue":"1","key":"200_CR18","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1007\/s10623-015-0036-z","volume":"79","author":"JC Faug\u00e8re","year":"2016","unstructured":"Faug\u00e8re, J.C., Otmani, A., Perret, L., de Portzamparc, F., Tillich, J.P.: Structural cryptanalysis of McEliece schemes with compact keys. Des. Codes Cryptogr. 79(1), 87\u2013112 (2016). https:\/\/doi.org\/10.1007\/s10623-015-0036-z","journal-title":"Des. Codes Cryptogr."},{"issue":"1","key":"200_CR19","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1109\/TIT.1962.1057683","volume":"8","author":"R Gallager","year":"1962","unstructured":"Gallager, R.: Low-density parity-check codes. IRE Trans. Inf. Theory 8(1), 21\u201328 (1962). https:\/\/doi.org\/10.1109\/TIT.1962.1057683","journal-title":"IRE Trans. Inf. Theory"},{"key":"200_CR20","doi-asserted-by":"crossref","unstructured":"Gueron, S.: Intel\u2019s new AES instructions for enhanced performance and security. In: FSE, vol. 5665, pp. 51\u201366. Springer (2009)","DOI":"10.1007\/978-3-642-03317-9_4"},{"key":"200_CR21","unstructured":"Gueron, S.: Intel\u00ae advanced encryption standard (AES) new instructions set Rev. 3.01. Intel Corporation. Intel Corporation. https:\/\/www.intel.com.bo\/content\/dam\/doc\/white-paper\/advanced-encryption-standard-new-instructions-set-paper.pdf (2010)"},{"issue":"01","key":"200_CR22","first-page":"7","volume":"4","author":"S Gueron","year":"2013","unstructured":"Gueron, S.: A j-lanes tree hashing mode and j-lanes SHA-256. J. Inf. Secur. 4(01), 7 (2013)","journal-title":"J. Inf. Secur."},{"issue":"03","key":"200_CR23","first-page":"91","volume":"5","author":"S Gueron","year":"2014","unstructured":"Gueron, S.: Parallelized hashing via j-lanes and j-pointers tree modes, with applications to SHA-256. J. Inf. Secur. 5(03), 91 (2014)","journal-title":"J. Inf. Secur."},{"issue":"14","key":"200_CR24","doi-asserted-by":"publisher","first-page":"549","DOI":"10.1016\/j.ipl.2010.04.011","volume":"110","author":"S Gueron","year":"2010","unstructured":"Gueron, S., Kounavis, M.: Efficient implementation of the Galois Counter Mode using a carry-less multiplier and a fast reduction algorithm. Inf. Process. Lett. 110(14), 549\u2013553 (2010). https:\/\/doi.org\/10.1016\/j.ipl.2010.04.011","journal-title":"Inf. Process. Lett."},{"key":"200_CR25","unstructured":"Gueron, S., Kounavis, M.E.: Intel\u00ae carry-less multiplication instruction and its usage for computing the GCM mode. White Paper (2010)"},{"issue":"04","key":"200_CR26","first-page":"319","volume":"3","author":"S Gueron","year":"2012","unstructured":"Gueron, S., Krasnov, V.: Simultaneous hashing of multiple messages. J. Inf. Secur. 3(04), 319 (2012)","journal-title":"J. Inf. Secur."},{"key":"200_CR27","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1007\/978-3-319-47560-8_12","volume-title":"Speeding up R-LWE Post-quantum Key Exchange","author":"S Gueron","year":"2016","unstructured":"Gueron, S., Schlieker, F.: Speeding up R-LWE Post-quantum Key Exchange, pp. 187\u2013198. Springer International Publishing, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-47560-8_12"},{"key":"200_CR28","doi-asserted-by":"publisher","first-page":"789","DOI":"10.1007\/978-3-662-53887-6_9","volume-title":"A Key Recovery Attack on MDPC with CCA Security Using Decoding Errors","author":"Q Guo","year":"2016","unstructured":"Guo, Q., Johansson, T., Stankovski, P.: A Key Recovery Attack on MDPC with CCA Security Using Decoding Errors, pp. 789\u2013815. Springer, Berlin (2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_9"},{"key":"200_CR29","volume-title":"Fundamentals of Error-Correcting Codes","author":"WC Huffman","year":"2010","unstructured":"Huffman, W.C., Pless, V.: Fundamentals of Error-Correcting Codes. Cambridge University Press, Cambridge (2010)"},{"key":"200_CR30","unstructured":"Intel Corporation.: Intel $$^{\\textregistered }$$ \u00ae Architecture Instruction Set Extensions and Future Features Programming Reference. https:\/\/software.HrBintel.com\/sites\/default\/files\/managed\/c5\/15\/architecture-instructiHrBon-set-extensionsprogramming-reference.pdf (2017). Retrieved 8 Jan 2019"},{"key":"200_CR31","unstructured":"Intel Corporation.: Intel Intrinsics Guide. https:\/\/software.intel.com\/sites\/landingpage\/IntrinsicsGuide\/ (2018). Retrieved 8 Jan 2019"},{"issue":"2","key":"200_CR32","doi-asserted-by":"crossref","first-page":"137","DOI":"10.1080\/00031305.1997.10473947","volume":"51","author":"BD Jovanovic","year":"1997","unstructured":"Jovanovic, B.D., Levy, P.S.: A look at the rule of three. Am. Stat. 51(2), 137\u2013139 (1997)","journal-title":"Am. Stat."},{"key":"200_CR33","doi-asserted-by":"publisher","first-page":"161","DOI":"10.1007\/BFb0024461","volume-title":"A Digital Signature Scheme Based on Random Error-Correcting Codes","author":"G Kabatianskii","year":"1997","unstructured":"Kabatianskii, G., Krouk, E., Smeets, B.: A Digital Signature Scheme Based on Random Error-Correcting Codes, pp. 161\u2013167. Springer, Berlin (1997). https:\/\/doi.org\/10.1007\/BFb0024461"},{"key":"200_CR34","first-page":"595","volume":"7","author":"A Karatsuba","year":"1963","unstructured":"Karatsuba, A., Ofman, Y.: Multiplication of multidigit numbers on automata. Sov. Phys. Dokl. 7, 595 (1963)","journal-title":"Sov. Phys. Dokl."},{"key":"200_CR35","unstructured":"Guido, B., Joan, D., Micha\u00ebl, P., Gilles, V. A., Ronny, V.K.: Keccak Code Package (KCP). https:\/\/github.com\/gvanas\/KeccakCodePackage (2017). Retrieved 30 Nov 2017"},{"issue":"3","key":"200_CR36","doi-asserted-by":"publisher","first-page":"44:1","DOI":"10.1145\/2700102","volume":"14","author":"IV Maurich","year":"2015","unstructured":"Maurich, I.V., Oder, T., G\u00fcneysu, T.: Implementing QC-MDPC McEliece encryption. ACM Trans. Embed Comput. Syst. 14(3), 44:1\u201344:27 (2015). https:\/\/doi.org\/10.1145\/2700102","journal-title":"ACM Trans. Embed Comput. Syst."},{"key":"200_CR37","first-page":"114","volume":"4244","author":"R McEliece","year":"1978","unstructured":"McEliece, R.: A public-key cryptosystem based on algebraic. Coding Thv 4244, 114\u2013116 (1978)","journal-title":"Coding Thv"},{"key":"200_CR38","doi-asserted-by":"publisher","first-page":"376","DOI":"10.1007\/978-3-642-05445-7_4","volume-title":"Compact McEliece Keys from Goppa Codes","author":"R Misoczki","year":"2009","unstructured":"Misoczki, R., Barreto, P.S.L.M.: Compact McEliece Keys from Goppa Codes, pp. 376\u2013392. Springer, Berlin (2009). https:\/\/doi.org\/10.1007\/978-3-642-05445-7_4"},{"key":"200_CR39","unstructured":"Misoczki, R., Tillich, J.P., Sendrier, N., Barreto, P.S.L.M.: MDPC-McEliece: new McEliece variants from moderate density parity-check codes. Cryptology ePrint Archive, Report 2012\/409. http:\/\/eprint.iacr.org\/2012\/409 (2012). Retrieved 8 Jan 2019"},{"key":"200_CR40","doi-asserted-by":"crossref","unstructured":"Misoczki, R., Tillich, J.P., Sendrier, N., Barreto, P.S.: MDPC-McEliece: New McEliece variants from moderate density parity-check codes. In: 2013 IEEE International Symposium on Information Theory, pp. 2069\u20132073 (2013). https:\/\/doi.org\/10.1109\/ISIT.2013.6620590","DOI":"10.1109\/ISIT.2013.6620590"},{"key":"200_CR41","doi-asserted-by":"crossref","unstructured":"Monico, C., Rosenthal, J., Shokrollahi, A.: Using low density parity check codes in the McEliece cryptosystem. In: 2000 IEEE International Symposium on Information Theory (Cat. No.00CH37060), IEEE, p. 215 (2000). https:\/\/doi.org\/10.1109\/ISIT.2000.866513","DOI":"10.1109\/ISIT.2000.866513"},{"key":"200_CR42","unstructured":"NIST.: NIST:Post-Quantum Cryptography\u2014call for proposals. https:\/\/csrc.nist.gov\/Projects\/Post-Quantum-Cryptography (2017). Retrieved 1 Nov 2018"},{"key":"200_CR43","unstructured":"OpenSSL.: OpenSSL, Commit: 2dbfa8444bdf7669a54006c4a83d1e60ba374528. https:\/\/github.com\/openssl\/openssl (2017). Retrieved 30 Sept 2017"},{"key":"200_CR44","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1007\/978-3-319-29360-8_7","volume-title":"An Efficient Attack on a Code-Based Signature Scheme","author":"A Phesso","year":"2016","unstructured":"Phesso, A., Tillich, J.P.: An Efficient Attack on a Code-Based Signature Scheme, pp. 86\u2013103. Springer International Publishing, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-29360-8_7"},{"key":"200_CR45","unstructured":"Gaudry, P., Brent, R., Zimmermann, P., Thom\u00e9, E.: gf2x-1.2. https:\/\/gforge.inria.fr\/projects\/gf2x\/ (2017). Retrieved 8 Jan 2019"},{"key":"200_CR46","unstructured":"Shoup, V.: Number Theory C++ Library (NTL) version 10.5.0. http:\/\/www.shoup.net\/ntl (2017). Retrieved 30 Nov 2017"},{"key":"200_CR47","doi-asserted-by":"crossref","unstructured":"Stern, J.: A new identification scheme based on syndrome decoding. In: Annual International Cryptology Conference, pp. 13\u201321. Springer (1993)","DOI":"10.1007\/3-540-48329-2_2"},{"key":"200_CR48","first-page":"714","volume":"3","author":"AL Toom","year":"1963","unstructured":"Toom, A.L.: The complexity of a scheme of functional elements realizing the multiplication of integers. Sov. Math. Dokl. 3, 714\u2013716 (1963)","journal-title":"Sov. Math. Dokl."}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s13389-018-00200-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-018-00200-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-018-00200-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,14]],"date-time":"2024-07-14T06:36:42Z","timestamp":1720939002000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s13389-018-00200-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,1,20]]},"references-count":48,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2019,11]]}},"alternative-id":["200"],"URL":"https:\/\/doi.org\/10.1007\/s13389-018-00200-4","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"value":"2190-8508","type":"print"},{"value":"2190-8516","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,1,20]]},"assertion":[{"value":"24 January 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 December 2018","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 January 2019","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}